Back to Database
Status published
Medium
CVE-2024-25994
PHOENIX CONTACT: Unintended script file upload in CHARX Series
Vulnerability Description
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25994
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Alex Plaskett of NCC Group
- McClaulay Hudson of NCC Group
More from PHOENIX CONTACT
View All →CVE-2025-41668
Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile
High
8.8
CVE-2025-41667
Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit script
High
8.8
CVE-2025-41666
Phoenix Contact: File access due to the replacement of a critical file used by the watchdog
High
8.8
CVE-2025-41665
Phoenix Contact: DoS of the PLC due to incorrect default permissions possible
Medium
6.5
CVE-2024-7734
Phoenix Contact: Multiple mGuard devices are vulnerable to a drain of open file descriptors.
Medium
5.3
Affected Vendor
PHOENIX CONTACT
View all reports →Affected Software
CHARX SEC-3000, CHARX SEC-3050, CHARX SEC-3100, CHARX SEC-3150
Vulnerable Versions:
0
Timeline
Official Publish:
March 12th, 2024
Last Modified:
January 24th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N